Elastic Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Elastic products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

3

Beyond CISA KEV

1

Sensor Observed

1

Virtual Patch Available

0

Elastic KEVs Added by Year

Loading...

4 Elastic KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2018-17246

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana...

High Not in CISA 20 May 2025
CVE-2019-7609

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the...

Confirmed In CISA 10 Jan 2022
CVE-2014-3120

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL...

Confirmed In CISA 25 Mar 2022
CVE-2015-1427

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism...

Confirmed In CISA 25 Mar 2022

Common Vulnerability Classes (CWE)

  • CWE-284 — Improper Access Control 1
  • CWE-73 — External Control of File Name or Path 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology